Senior SOC Platform Engineer

IndiaPosted Jul 20, 2026

Senior SOC Platform Engineer
(CrowdStrike Next-Gen SIEM, SOAR & EDR – Microsoft Sentinel Secondary)

Position Summary

We are seeking a highly skilled Senior SOC Platform Engineer with strong expertise in CrowdStrike Falcon Next-Generation SIEM, Falcon Fusion SOAR, Falcon EDR, Python automation, threat hunting, and detection engineering. This role is responsible for engineering, optimizing, and scaling SOC platform capabilities that enable advanced threat detection, incident response, security analytics, and SOC transformation initiatives.

The successful candidate will act as a technical lead for security platform engineering, supporting customer onboarding, SIEM/SOAR content development, automation initiatives, threat intelligence integration, and SOC maturity programs. Microsoft Sentinel experience is required as a secondary platform.

Job Description

• Design, deploy, manage, and optimize CrowdStrike Falcon Next-Gen SIEM environments.
• Configure detections, correlation rules, dashboards, reports, and alerting logic.
• Engineer Falcon Fusion SOAR workflows for automated incident response.
• Manage Falcon EDR policies, detections, investigations, and response actions.
• Develop Python-based automation for SOC operations and threat-hunting activities.
• Integrate third-party security telemetry and threat intelligence feeds.
• Build MITRE ATT&CK aligned detection content.
• Conduct proactive threat hunting using Falcon, Defender, and Notebook-based analytics.
• Support Microsoft Sentinel analytics, playbooks, data connectors, and KQL content development.
• Maintain platform documentation, SOPs, runbooks, and architecture standards.

Key Responsibilities

• Lead engineering efforts for Falcon SIEM, SOAR, and EDR platforms.
• Develop and tune detection use cases and correlation logic.
• Create reusable automation and onboarding frameworks.
• Support SOC operations through enrichment and orchestration.
• Ensure telemetry quality, data normalization, and coverage optimization.
• Participate in threat hunting and purple-team exercises.
• Mentor analysts and platform engineers.
• Support client onboarding and SOC transformation programs.
• Drive continuous improvement and operational excellence.

Required Qualifications

• 5–10+ years of experience in Security Operations, SIEM, SOAR, EDR, or Security Engineering.
• Hands-on experience with CrowdStrike Falcon Next-Gen SIEM.
• Experience with Falcon Fusion SOAR and Falcon EDR.
• Strong knowledge of threat detection, incident response, and threat hunting.
• Proficiency in Python, REST APIs, PowerShell, and automation frameworks.
• Working knowledge of Microsoft Sentinel, KQL, Azure Logic Apps, and Microsoft Defender.
• Experience with cloud platforms including Azure, AWS, and GCP.
• Strong communication and stakeholder management skills.

Preferred Skills

• Splunk Enterprise Security
• Microsoft Security Copilot
• ServiceNow Security Operations
• Palo Alto Cortex XSOAR
• Infrastructure as Code (Terraform, ARM, Bicep)
• CI/CD and DevSecOps concepts

Preferred Certifications

• CrowdStrike Certified Falcon Administrator (CCFA)
• CrowdStrike Certified Falcon Responder (CCFR)
• CrowdStrike Certified Falcon Hunter (CCFH)
• Microsoft SC-200
• Microsoft AZ-500
• CISSP
• CISM
• GCIH

Experience Level

Senior Individual Contributor / Lead SOC Platform Engineer

Key Responsibilities

• Lead engineering efforts for Falcon SIEM, SOAR, and EDR platforms.
• Develop and tune detection use cases and correlation logic.
• Create reusable automation and onboarding frameworks.
• Support SOC operations through enrichment and orchestration.
• Ensure telemetry quality, data normalization, and coverage optimization.
• Participate in threat hunting and purple-team exercises.
• Mentor analysts and platform engineers.
• Support client onboarding and SOC transformation programs.
• Drive continuous improvement and operational excellence.

Required Qualifications

• 5–10+ years of experience in Security Operations, SIEM, SOAR, EDR, or Security Engineering.
• Hands-on experience with CrowdStrike Falcon Next-Gen SIEM.
• Experience with Falcon Fusion SOAR and Falcon EDR.
• Strong knowledge of threat detection, incident response, and threat hunting.
• Proficiency in Python, REST APIs, PowerShell, and automation frameworks.
• Working knowledge of Microsoft Sentinel, KQL, Azure Logic Apps, and Microsoft Defender.
• Experience with cloud platforms including Azure, AWS, and GCP.
• Strong communication and stakeholder management skills.

Want jobs like this matched to you?

Swoopd scores fresh postings against your résumé so you only see the matches that matter.

Get started free